Docs / Guides

Setting up a Family Vault

A Family Vault (Family plan) is a shared, encrypted document space that lives in a folder your family already controls — a NAS or WebDAV share, a Syncthing folder, or a cloud drive's shared folder synced to each computer. Keepsake runs no server: who can read what is decided by cryptographic keys, not by an access-control list a company could change or leak.

How access works

  • Every member has a personal family identity (an X25519 key pair). The private half never leaves their own vault; the public half is what the owner uses to grant access.
  • The family's master key, and one key per category (Finance, IDs, Medical, …), are sealed to each member's public key. You can open exactly the categories you were granted — nothing else, and nobody outside the family can open anything at all.
  • Revoking a category (or removing a member) rotates the keys and re-encrypts those documents, so the change is real, not cosmetic. One honest caveat: copies someone already downloaded cannot be recalled.

Create the family (owner)

  1. Open Family Vault — on Windows it's Family Access in the sidebar; on Android it's the Family tab; in the web app it's under Premium tools.
  2. Point it at the shared folder. On Windows pick the folder (any synced/NAS path works); on Android pick any folder another app syncs (Syncthing, a cloud drive's folder); in the browser enter your WebDAV address.
  3. Choose Create family and give it a name.

Add members

  1. Each member opens Family Vault on their device and taps My enrolment code — a short KSF1.… code containing their name and public key only. It is safe to send by any channel; Secure Send is ideal.
  2. The owner chooses Add member, pastes the code, and picks a role.
  3. The owner then grants categories — e.g. IDs to everyone, Finance to the adults only.

Share and read documents

  • Share a file encrypts it under the category's key and puts it in the shared folder; every member the category was granted to can open it from their own device.
  • Members without the grant still see that a document exists (title and category) but cannot decrypt a single byte of it.

Removing someone

Removing a member rotates the family key and every category key they held, and re-encrypts affected documents. Ask everyone to sync before you do it — members' unsynced changes from before the removal are lost.


Was this page helpful?

If something here is missing, wrong, or just unclear, say so — corrections to these pages usually start as a comment.

Leave a comment Ask the community →

Comments

No comments yet — be the first.

Sign in to comment — website account only; your vault never touches it.